CVE Feed

    Dashboard / CVE

    5.9
    Medium

    CVE-2024-36378

    Last Modified: 27 Jan 2025

    In JetBrains TeamCity before 2024.03.2 server was susceptible to DoS attacks with incorrect auth tokens

    Published: 29 May 2024
    6.5
    Medium

    CVE-2024-36377

    Last Modified: 27 Jan 2025

    In JetBrains TeamCity before 2024.03.2 certain TeamCity API endpoints did not check user permissions

    Published: 29 May 2024
    6.5
    Medium

    CVE-2024-36376

    Last Modified: 27 Jan 2025

    In JetBrains TeamCity before 2024.03.2 users could perform actions that should not be available to them based on their permissions

    Published: 29 May 2024
    5.3
    Medium

    CVE-2024-36375

    Last Modified: 27 Jan 2025

    In JetBrains TeamCity before 2024.03.2 technical information regarding TeamCity server could be exposed

    Published: 29 May 2024
    4.6
    Medium

    CVE-2024-36374

    Last Modified: 27 Jan 2025

    In JetBrains TeamCity before 2024.03.2 stored XSS via build step settings was possible

    Published: 29 May 2024
    4.6
    Medium

    CVE-2024-36373

    Last Modified: 27 Jan 2025

    In JetBrains TeamCity before 2024.03.2 several stored XSS in untrusted builds settings were possible

    Published: 29 May 2024
    4.6
    Medium

    CVE-2024-36372

    Last Modified: 27 Jan 2025

    In JetBrains TeamCity before 2023.05.6 reflected XSS on the subscriptions page was possible

    Published: 29 May 2024
    4.6
    Medium

    CVE-2024-36371

    Last Modified: 7 Feb 2025

    In JetBrains TeamCity before 2023.05.6, 2023.11.5 stored XSS in Commit status publisher was possible

    Published: 29 May 2024
    4.6
    Medium

    CVE-2024-36370

    Last Modified: 16 Dec 2024

    In JetBrains TeamCity before 2022.04.7, 2022.10.6, 2023.05.6, 2023.11.5 stored XSS via OAuth connection settings was possible

    Published: 29 May 2024
    4.6
    Medium

    CVE-2024-36369

    Last Modified: 16 Dec 2024

    In JetBrains TeamCity before 2022.04.7, 2022.10.6, 2023.05.6, 2023.11.5 stored XSS via issue tracker integration was possible

    Published: 29 May 2024
    4.6
    Medium

    CVE-2024-36368

    Last Modified: 16 Dec 2024

    In JetBrains TeamCity before 2022.04.7, 2022.10.6, 2023.05.6, 2023.11.5 reflected XSS via OAuth provider configuration was possible

    Published: 29 May 2024
    4.6
    Medium

    CVE-2024-36367

    Last Modified: 16 Dec 2024

    In JetBrains TeamCity before 2022.04.7, 2022.10.6, 2023.05.6, 2023.11.5 stored XSS via third-party reports was possible

    Published: 29 May 2024
    5.4
    Medium

    CVE-2024-36366

    Last Modified: 16 Dec 2024

    In JetBrains TeamCity before 2022.04.7, 2022.10.6, 2023.05.6, 2023.11.5 an XSS could be executed via certain report grouping and filtering operations

    Published: 29 May 2024
    6.8
    Medium

    CVE-2024-36365

    Last Modified: 16 Dec 2024

    In JetBrains TeamCity before 2022.04.7, 2022.10.6, 2023.05.6, 2023.11.5, 2024.03.2 a third-party agent could impersonate a cloud agent

    Published: 29 May 2024
    6.5
    Medium

    CVE-2024-36364

    Last Modified: 16 Dec 2024

    In JetBrains TeamCity before 2022.04.7, 2022.10.6, 2023.05.6, 2023.11.5 improper access control in Pull Requests and Commit status publisher build features was possible

    Published: 29 May 2024
    4.6
    Medium

    CVE-2024-36363

    Last Modified: 16 Dec 2024

    In JetBrains TeamCity before 2022.04.7, 2022.10.6, 2023.05.6, 2023.11.5 several Stored XSS in code inspection reports were possible

    Published: 29 May 2024
    6.5
    Medium

    CVE-2024-36362

    Last Modified: 16 Dec 2024

    In JetBrains TeamCity before 2022.04.7, 2022.10.6, 2023.05.6, 2023.11.5, 2024.03.2 path traversal allowing to read files from server was possible

    Published: 29 May 2024
    6.5
    Medium

    CVE-2024-25975

    Last Modified: 15 Apr 2026

    The application implements an up- and downvote function which alters a value within a JSON file. The POST parameters are not filtered properly and therefore an arbitrary file can be overwritten. The file can be controlled by an authenticated attacker, the content cannot be controlled. It is possible to overwrite all files for which the webserver has write access. It is required to supply a relative path (path traversal).

    Published: 29 May 2024
    8.3
    High

    CVE-2024-5185

    Last Modified: 15 Apr 2026

    The EmbedAI application is susceptible to security issues that enable Data Poisoning attacks. This weakness could result in the application becoming compromised, leading to unauthorized entries or data poisoning attacks, which are delivered by a CSRF vulnerability due to the absence of a secure session management implementation and weak CORS policies weakness. An attacker can direct a user to a malicious webpage that exploits a CSRF vulnerability within the EmbedAI application. By leveraging this CSRF vulnerability, the attacker can deceive the user into inadvertently uploading and integrating incorrect data into the application’s language model.

    Published: 29 May 2024
    7.4
    High

    CVE-2023-42005

    Last Modified: 18 Aug 2025

    IBM Db2 on Cloud Pak for Data and Db2 Warehouse on Cloud Pak for Data 3.5, 4.0, 4.5, 4.6, 4.7, and 4.8 could allow a user with access to the Kubernetes pod, to make system calls compromising the security of containers. IBM X-Force ID: 265264.

    Published: 29 May 2024
    6.4
    Medium

    CVE-2024-5039

    Last Modified: 8 Apr 2026

    The HUSKY – Products Filter Professional for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in all versions up to, and including, 1.3.5.3 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

    Published: 29 May 2024
    7.3
    High

    CVE-2024-25977

    Last Modified: 15 Apr 2026

    The application does not change the session token when using the login or logout functionality. An attacker can set a session token in the victim's browser (e.g. via XSS) and prompt the victim to log in (e.g. via a redirect to the login page). This results in the victim's account being taken over.

    Published: 29 May 2024
    6.1
    Medium

    CVE-2024-25976

    Last Modified: 15 Apr 2026

    When LDAP authentication is activated in the configuration it is possible to obtain reflected XSS execution by creating a custom URL that the victim only needs to open in order to execute arbitrary JavaScript code in the victim's browser. This is due to a fault in the file login.php where the content of "$_SERVER['PHP_SELF']" is reflected into the HTML of the website. Hence the attacker does not need a valid account in order to exploit this issue.

    Published: 29 May 2024
    6.3
    Medium

    CVE-2024-27313

    Last Modified: 27 Nov 2024

    Zoho ManageEngine PAM360 is vulnerable to Stored XSS vulnerability. This vulnerability is applicable only in the version 6610.

    Published: 29 May 2024
    8.8
    High

    CVE-2024-28826

    Last Modified: 4 Dec 2024

    Improper restriction of local upload and download paths in check_sftp in Checkmk before 2.3.0p4, 2.2.0p27, 2.1.0p44, and in Checkmk 2.0.0 (EOL) allows attackers with sufficient permissions to configure the check to read and write local files on the Checkmk site server.

    Published: 29 May 2024
    9.1
    Critical

    CVE-2024-3412

    Last Modified: 15 Apr 2026

    The WP STAGING WordPress Backup Plugin – Migration Backup Restore plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the wpstg_processing AJAX action in all versions up to, and including, 3.4.3. This makes it possible for authenticated attackers, with administrator-level access and above, to upload arbitrary files on the affected site's server which may make remote code execution possible.

    Published: 29 May 2024
    6.4
    Medium

    CVE-2024-5086

    Last Modified: 8 Apr 2026

    The Essential Addons for Elementor PRO – Best Elementor Templates, Widgets, Kits & WooCommerce Builders plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Team Member Carousel widget in all Pro versions up to, and including, 5.8.14 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

    Published: 29 May 2024
    4.8
    Medium

    CVE-2024-3937

    Last Modified: 21 May 2025

    The Playlist for Youtube WordPress plugin through 1.32 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

    Published: 29 May 2024
    4.8
    Medium

    CVE-2024-3921

    Last Modified: 21 May 2025

    The Gianism WordPress plugin through 5.1.0 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

    Published: 29 May 2024
    9.1
    Critical

    CVE-2024-3050

    Last Modified: 21 May 2025

    The Site Reviews WordPress plugin before 7.0.0 retrieves client IP addresses from potentially untrusted headers, allowing an attacker to manipulate its value. This may be used to bypass IP-based blocking

    Published: 29 May 2024
    4.4
    Medium

    CVE-2024-4419

    Last Modified: 8 Apr 2026

    The Fetch JFT plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 1.8.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfiltered_html has been disabled.

    Published: 29 May 2024
    8.1
    High

    CVE-2024-4611

    Last Modified: 8 Apr 2026

    The AppPresser plugin for WordPress is vulnerable to improper missing encryption exception handling on the 'decrypt_value' and on the 'doCookieAuth' functions in all versions up to, and including, 4.3.2. This makes it possible for unauthenticated attackers to log in as any existing user on the site, such as an administrator, if they previously used the login via the plugin API. This can only be exploited if the 'openssl' php extension is not loaded on the server.

    Published: 29 May 2024
    8.8
    High

    CVE-2023-6743

    Last Modified: 8 Apr 2026

    The Unlimited Elements For Elementor (Free Widgets, Addons, Templates) plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 1.5.89 via the template import functionality. This makes it possible for authenticated attackers, with contributor access and above, to execute code on the server.

    Published: 29 May 2024
    5.3
    Medium

    CVE-2024-0434

    Last Modified: 15 Apr 2026

    The WordPress Tour & Travel Booking Plugin for WooCommerce – WpTravelly plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'ttbm_new_place_save' function in all versions up to, and including, 1.7.1. This makes it possible for unauthenticated attackers to create and publish new place posts. This function is also vulnerable to CSRF.

    Published: 29 May 2024
    9.8
    Critical

    CVE-2024-5150

    Last Modified: 15 Apr 2026

    The Login with phone number plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 1.7.26. This is due to the 'activation_code' default value is empty, and the not empty check is missing in the 'lwp_ajax_register' function. This makes it possible for unauthenticated attackers to log in as any existing user on the site, such as an administrator, if they have access to the user email. The vulnerability is patched in version 1.7.26, but there is an issue in the patch that causes the entire function to not work, and this issue is fixed in version 1.7.27.

    Published: 29 May 2024
    8.8
    High

    CVE-2024-5204

    Last Modified: 15 Apr 2026

    The Swiss Toolkit For WP plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 1.0.7. This is due to the plugin storing custom data in post metadata without an underscore prefix. This makes it possible for authenticated attackers with contributor-level and above permissions to log in as any existing user on the site, such as an administrator.

    Published: 29 May 2024
    8.1
    High

    CVE-2024-36427

    Last Modified: 15 Apr 2026

    The file-serving function in TARGIT Decision Suite before 24.06.19002 (TARGIT Decision Suite 2024 – June) allows authenticated attackers to read or write to server files via a crafted file request. This can allow code execution via a .xview file.

    Published: 29 May 2024
    8.2
    High

    CVE-2024-21512

    Last Modified: 15 Apr 2026

    Versions of the package mysql2 before 3.9.8 are vulnerable to Prototype Pollution due to improper user input sanitization passed to fields and tables when using nestTables.

    Published: 29 May 2024
    7.8
    High

    CVE-2024-36015

    Last Modified: 4 Nov 2025

    In the Linux kernel, the following vulnerability has been resolved: ppdev: Add an error check in register_device In register_device, the return value of ida_simple_get is unchecked, in witch ida_simple_get will use an invalid index value. To address this issue, index should be checked after ida_simple_get. When the index value is abnormal, a warning message should be printed, the port should be dropped, and the value should be recorded.

    Published: 29 May 2024
    4.8
    Medium

    CVE-2024-31079

    Last Modified: 13 Feb 2025

    When NGINX Plus or NGINX OSS are configured to use the HTTP/3 QUIC module, undisclosed HTTP/3 requests can cause NGINX worker processes to terminate or cause other potential impact. This attack requires that a request be specifically timed during the connection draining process, which the attacker has no visibility and limited influence over.

    Published: 29 May 2024
    5.3
    Medium

    CVE-2024-35200

    Last Modified: 13 Feb 2025

    When NGINX Plus or NGINX OSS are configured to use the HTTP/3 QUIC module, undisclosed HTTP/3 requests can cause NGINX worker processes to terminate.

    Published: 29 May 2024
    7.8
    High

    CVE-2024-36016

    Last Modified: 4 Aug 2026

    In the Linux kernel, the following vulnerability has been resolved: tty: n_gsm: fix possible out-of-bounds in gsm0_receive() Assuming the following: - side A configures the n_gsm in basic option mode - side B sends the header of a basic option mode frame with data length 1 - side A switches to advanced option mode - side B sends 2 data bytes which exceeds gsm->len Reason: gsm->len is not used in advanced option mode. - side A switches to basic option mode - side B keeps sending until gsm0_receive() writes past gsm->buf Reason: Neither gsm->state nor gsm->len have been reset after reconfiguration. Fix this by changing gsm->count to gsm->len comparison from equal to less than. Also add upper limit checks against the constant MAX_MRU in gsm0_receive() and gsm1_receive() to harden against memory corruption of gsm->len and gsm->mru. All other checks remain as we still need to limit the data according to the user configuration and actual payload size.

    Published: 29 May 2024
    6.5
    Medium

    CVE-2024-32760

    Last Modified: 13 Feb 2025

    When NGINX Plus or NGINX OSS are configured to use the HTTP/3 QUIC module, undisclosed HTTP/3 encoder instructions can cause NGINX worker processes to terminate or cause or other potential impact.

    Published: 29 May 2024
    5.3
    Medium

    CVE-2024-34161

    Last Modified: 13 Feb 2025

    When NGINX Plus or NGINX OSS are configured to use the HTTP/3 QUIC module and the network infrastructure supports a Maximum Transmission Unit (MTU) of 4096 or greater without fragmentation, undisclosed QUIC packets can cause NGINX worker processes to leak previously freed memory.

    Published: 29 May 2024
    5.5
    Medium

    CVE-2024-36014

    Last Modified: 4 Nov 2025

    In the Linux kernel, the following vulnerability has been resolved: drm/arm/malidp: fix a possible null pointer dereference In malidp_mw_connector_reset, new memory is allocated with kzalloc, but no check is performed. In order to prevent null pointer dereferencing, ensure that mw_state is checked before calling __drm_atomic_helper_connector_reset.

    Published: 29 May 2024
    5.3
    Medium

    CVE-2024-5437

    Last Modified: 9 Dec 2024

    A vulnerability was found in SourceCodester Simple Online Bidding System 1.0. It has been classified as problematic. Affected is the function save_category of the file /admin/index.php?page=categories. The manipulation of the argument name leads to cross site scripting. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. VDB-266442 is the identifier assigned to this vulnerability.

    Published: 28 May 2024
    6.3
    Medium

    CVE-2024-36112

    Last Modified: 26 Aug 2025

    Nautobot is a Network Source of Truth and Network Automation Platform. A user with permissions to view Dynamic Group records (`extras.view_dynamicgroup` permission) can use the Dynamic Group detail UI view (`/extras/dynamic-groups/<uuid>/`) and/or the members REST API view (`/api/extras/dynamic-groups/<uuid>/members/`) to list the objects that are members of a given Dynamic Group. In versions of Nautobot between 1.3.0 (where the Dynamic Groups feature was added) and 1.6.22 inclusive, and 2.0.0 through 2.2.4 inclusive, Nautobot fails to restrict these listings based on the member object permissions - for example a Dynamic Group of Device objects will list all Devices that it contains, regardless of the user's `dcim.view_device` permissions or lack thereof. This issue has been fixed in Nautobot versions 1.6.23 and 2.2.5. Users are advised to upgrade. This vulnerability can be partially mitigated by removing `extras.view_dynamicgroup` permission from users however a full fix will require upgrading.

    Published: 28 May 2024
    6.5
    Medium

    CVE-2023-30314

    Last Modified: 15 Apr 2026

    An issue discovered in 360 V6G, 360 T5G, 360 T6M, and 360 P1 routers allows attackers to hijack TCP sessions which could lead to a denial of service.

    Published: 28 May 2024
    6.5
    Medium

    CVE-2024-23580

    Last Modified: 15 Apr 2026

    HCL DRYiCE Optibot Reset Station is impacted by insecure encryption of One-Time Passwords (OTPs). This could allow an attacker with access to the database to recover some or all encrypted values.

    Published: 28 May 2024
    6.5
    Medium

    CVE-2024-23579

    Last Modified: 15 Apr 2026

    HCL DRYiCE Optibot Reset Station is impacted by insecure encryption of security questions. This could allow an attacker with access to the database to recover some or all encrypted values.

    Published: 28 May 2024